VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2026-60678High· 8.8
2mo ago

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CVE-2026-61311High· 8.8
2mo ago

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-61188High· 7.5
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privile…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.33%via NVD
CVE-2026-61183Critical· 9.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated …

▾ Midnightoracle · agile_product_lifecycle_management_for_processEPSS 0.51%via NVD
CVE-2026-61180High· 8.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.43%via NVD
CVE-2026-61179High· 8.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.43%via NVD
CVE-2026-61178Critical· 9.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticat…

▾ Midnightoracle · agile_product_lifecycle_management_for_processEPSS 0.51%via NVD
CVE-2026-61110High· 8.8
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …

▾ Twilightoracle · applications_dbaEPSS 0.43%via NVD
CVE-2026-60615High· 8.2
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.35%via NVD
CVE-2026-60599High· 8.1
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacke…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.36%via NVD
CVE-2026-60598High· 7.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attac…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.33%via NVD
CVE-2026-60568Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-60558High· 8.1
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · webcenter_sitesEPSS 0.39%via NVD
CVE-2026-56654High
2mo ago

Gitea: Privilege Escalation via Access Token Scope Escalation in API

Gitea: Privilege Escalation via Access Token Scope Escalation in API

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.60%via GHSA
CVE-2026-58423High· 7.7
2mo ago

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.54%via GHSA
CVE-2026-61740Critical
2mo ago

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

▾ Midnightlightrag-hku · lightrag-hkuEPSS 0.66%via GHSA
CVE-2026-16210High· 7.3
2mo ago

A vulnerability was found in newpanjing simpleui 2026.01.13

A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. R…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-16209High· 7.3
2mo ago

A vulnerability has been found in Gerapy up to 0.9.13

A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The a…

▾ TwilightEPSS 0.71%via NVD
CVE-2026-16198Medium· 5.6
2mo ago

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument all…

▾ SunlitEPSS 0.63%via NVD
CVE-2024-58363Medium· 6.3
2mo ago

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database i…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-47865Critical· 9.8
2mo ago

VMware Avi Load Balancer contains an authentication bypass vulnerability

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-16083Medium· 5.3
2mo ago

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by …

▾ SunlitEPSS 0.72%via NVD
CVE-2026-16076Medium· 6.3
2mo ago

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username …

▾ SunlitEPSS 0.51%via NVD
CVE-2026-22752Critical· 9.6
2mo ago

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…

▾ Midnightbroadcom · spring_authorization_serverEPSS 0.48%via NVD
CVE-2026-55445None
2mo ago

Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript

Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not /open/user/init, while rewrite('/open…

▾ SunlitEPSS 0.66%via NVD
CVE-2026-52893None
2mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, withou…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-45363Critical· 9.1
2mo ago

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', paylo…

▾ Midnightjwt · ruby-jwtEPSS 0.36%via NVD
CVE-2026-50338High· 8.2PoC
2mo ago

Azure Spring Apps Elevation of Privilege Vulnerability

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Spring AppsEPSS 0.52%via CVEORG
CVE-2026-57107High· 7.8
2mo ago

Windows Admin Center Elevation of Privilege Vulnerability

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows Admin CenterEPSS 0.30%via CVEORG
CVE-2026-56185Medium· 6.5
2mo ago

Windows Admin Center Information Disclosure Vulnerability

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows Admin CenterEPSS 0.84%via CVEORG
CWE-287 vulnerabilities (CVEs) — page 11 · VulnSea